Why small businesses have become a favourite target for cybercriminals

Automated attacks do not pick victims by size. They pick whatever is easiest to break into, and small firms often are.

By CSN Newsroom

Illustration: Why small businesses have become a favourite target for cybercriminals

Illustration Illustration: CybersecurityNews.ca

Analysis

Key points

  • Automated scans look for weak passwords and unpatched systems
  • Small suppliers can be a path into larger clients
  • The basics still stop most attacks

Large companies make headlines when they are breached, but small and medium-sized businesses face many of the same attacks with far fewer people to defend against them.

Easier targets, automated attacks

Criminals increasingly use automated tools that scan the internet for weak passwords, exposed remote access and unpatched software. They do not choose victims by size; they choose whatever is easiest to break into. Without a dedicated security team, small businesses are often easier to get into and slower to notice an intrusion.

A path to bigger clients

Suppliers and service providers can also be a stepping stone into the larger organizations they work with, which is why more contracts now ask about security practices.

What makes the biggest difference

The basics still stop most attacks: multi-factor authentication, prompt updates, tested backups and staff who know how to spot phishing. The Canadian Centre for Cyber Security publishes free baseline security controls written for small and medium organizations.

Editor's Picks

The best of The Rightup, delivered to you weekly.

On Display
Illustration: How to turn on multi-factor authentication in Microsoft 365

How to turn on multi-factor authentication in Microsoft 365

Illustration: How to report a phishing email or scam text in Canada

How to report a phishing email or scam text in Canada

AMD security advisory (AV26-1014)